SB2018101025 - Multiple vulnerabilities in TecRail Responsive FileManager
Published: October 10, 2018 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper Authentication (CVE-ID: CVE-2018-18061)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
2) Cross-site scripting (CVE-ID: CVE-2018-18062)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
Remediation
Install update from vendor's website.